Open Source Conference Luxembourg

Flipping Open Source's Evidence Gap in Public Procurement

Europe has decided open source is strategic to its digital sovereignty. The CRA, NIS2, DORA, the AI Act and the 2026 Cloud and AI Development Act all lean on it, and the Commission's revised Open Source Strategy names software catalogues directly. Yet in procurement, open source still loses — not on merit, but on paperwork. A proprietary vendor arrives with a pre-packaged evidence apparatus: one sales contact, reference lists, compliance and accessibility documentation. The equivalent open source project arrives with a repository, a README and other scattered resources. Buyers who would choose it cannot easily establish what exists, what meets their criteria, or who can deliver — so decisions collapse to price.

This talk presents the instrument to flip that asymmetry: a decentralised evidence layer built on publiccode.yml — the standard already mandatory in Italy, live on Germany's openCode.de, and required by the EU Open Source Catalogue (640+ projects). Evidence of supply chains, upstream contributions and real-world use becomes verifiable and queryable: no central gatekeeper, no imposed scores. What the evidence means stays with buyers and their jurisdictions.

The result is something no fragmented proprietary landscape can offer: one queryable, openly contributed evidence commons. You will leave knowing what already runs today, what is missing, and how to engage — as a vendor, a public buyer, or a catalogue operator — without waiting for Brussels to finish.


In June 2026 the European Commission published its Tech Sovereignty Package, including the revised Open Source Strategy and the proposed Cloud and AI Development Act. Both lean on open source solution catalogues and on connecting the ones Europe already runs. What neither builds is the data layer underneath: the CRA, NIS2, DORA and the AI Act each demand supply-chain or sovereignty evidence, and none defines a standard format. Every regime mandates evidence; no regime says what it looks like.

This talk argues the procurement barrier is institutional, not legal — the directives already permit non-price criteria; they collapse to price because qualitative judgments are too costly to defend against challenge, and because a single proprietary vendor hands the buyer pre-packaged evidence while the equivalent open source facts sit scattered across forges, package registries and contributor records. Procurement defaults to the incumbent not because it is better, but because it is easier to document.

The instrument presented closes that gap by evolving publiccode.yml into a decentralised evidence layer: supply-chain references (SBOM, OpenSSF Scorecard, security policy) that make CRA/NIS2 artifacts double as procurement quality signals; project-endorsed contribution-credit registries that turn "Made in Europe" from vendor self-declaration into verifiable upstream evidence; usage registries that make "widely deployed yet under-funded" a queryable signal for sovereignty funding. Registries are themselves discoverable, so any catalogue can aggregate from any conforming one — federation with no central gatekeeper, the same pattern already feeding national catalogues into the EU Open Source Catalogue today. One honest caveat frames the ask: today publiccode.yml is used almost exclusively by open source software developed in or for the public sector, because the catalogues that mandate it reach no further. The evolved sections are designed to change that: supply-chain references, contribution credits and usage declarations give any open source project a concrete reason to publish the file, not only software already sitting in a government catalogue.

A design principle keeps it durable: the standard defines what is collected and how, never metrics, thresholds or scores. Interpretation belongs to consumers and jurisdictions — and catalogues bring their own perspective on top, through the data sources they connect, the filters they offer and the scoring algorithms they apply. The standard's neutrality is what lets those differing perspectives coexist over the same evidence.

The close is practical: three concrete asks by audience role — vendors publish a complete publiccode.yml and point at their contribution credits; public buyers ask for machine-readable evidence in their next tender, defensibly, now; catalogue and forge operators crawl the usage declarations and adopt the supply-chain section. Leading by example in digital sovereignty starts with making sovereignty measurable.

Lukas Kahwe Smith

Lukas Kahwe Smith is a long-time open source contributor: a release manager for PHP 5.3 and a former member of the Symfony core team, with two decades of building, shipping, and adopting open source in production. He is a regular speaker at conferences around the world.

At Bern University of Applied Sciences (BFH) he works at the intersection of open source and public procurement. He leads intelliprocure.ch, a platform that collects public-procurement tenders and makes them transparent by structuring them, with tooling planned to help authorities write better tenders, for example through procurement-criteria best practices. He also works on ossdirectory.com, the only open source catalog that connects projects with the vendors who support them.